Labels for data security system asset management
Abstract
Methods, systems, and devices for generating and applying function-based and/or rule-based labels to data records for a data security system are described. Such labels may be used for querying of data records. A user of a data security system may define metadata criteria for triggering generation of a label. In some examples, the user may define a function that may transform the metadata that satisfies the triggering criteria for a data record into a label to apply to the data record. In some examples, the user may define a rule that indicates a label to apply to the data record(s) that satisfy the metadata criteria. A user may query the database for records based on the labels applied to the data records in a consistent format expected by the administrative user.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method, comprising:
receiving, by a data security system and via a user interface associated with a client account of the data security system, a function associated with label generation, wherein the function indicates a type of metadata and a transformation to apply to the type of metadata; performing, by the data security system, a scan of a database that stores a plurality of data records associated with a respective plurality of computing assets associated with the client account, the plurality of data records comprising identifiers for the respective plurality of computing assets and metadata associated with the respective plurality of computing assets; identifying, by the data security system and based on the scan, a data record of the plurality of data records that includes metadata that matches the type of metadata; generating, by the data security system, a label based on application of the transformation to the metadata in accordance with the function; adding, by the data security system, the label to the data record; and storing, by the data security system, the data record with the label in the database.
2 . The method of claim 1 , further comprising:
receiving, by the data security system, a second data record associated with a second computing asset associated with the client account for addition to the database, the second data record comprising a second identifier and second metadata associated with the second computing asset; identifying, by the data security system, that the second metadata matches the type of metadata; generating, by the data security system, a second label based on application of the transformation to the second metadata in accordance with the function; adding, by the data security system, the second label to the second data record; and storing, by the data security system, the second data record with the second label in the database.
3 . The method of claim 1 , further comprising:
identifying, by the data security system and based on the scan, a second data record of the plurality of data records that includes second metadata that matches the type of metadata; generating, by the data security system, a second label based on application of the transformation to the second metadata in accordance with the function; adding, by the data security system, the second label to the second data record; and storing, by the data security system, the second data record with the label in the database.
4 . The method of claim 1 , further comprising:
receiving, by the data security system and via the user interface or a second user interface associated with the client account, a second function associated with label generation, wherein the second function indicates a second type of metadata and a second transformation to apply to the second type of metadata; identifying, by the data security system and based on the scan, that the data record includes second metadata that matches the second type of metadata; generating, by the data security system, a second label based on application of the second transformation to the second metadata in accordance with the function; adding, by the data security system, the second label to the data record; and storing, by the data security system, the data record with the second label in the database.
5 . The method of claim 1 , further comprising:
receiving, by the data security system and via the user interface or a second user interface associated with the client account, a second function associated with label generation, wherein the second function indicates a second type of metadata and a second transformation to apply to the second type of metadata; identifying, by the data security system and based on the scan, that a second data record of the plurality of data records includes second metadata that matches the second type of metadata; generating, by the data security system, a second label based on application of the second transformation to the second metadata in accordance with the function; adding, by the data security system, the second label to the second data record; and storing, by the data security system, the second data record with the second label in the database.
6 . The method of claim 1 , further comprising:
receiving, by the data security system and via the user interface or a second user interface associated with the client account, a query that indicates the label; retrieving, from the database and based on the query, a set of data records that include the label, the set of data records including the data record; and causing, by the data security system, display of the set of data records at the user interface or the second user interface.
7 . The method of claim 1 , further comprising:
receiving, by the data security system and via the user interface or a second user interface associated with the client account, a rule associated with label generation, wherein the rule indicates a metadata criteria and a second label; identifying, by the data security system and based on the scan, that the metadata or second metadata of the data record matches the metadata criteria; adding, by the data security system, the second label to the data record based on identifying that the metadata or the second metadata of the data record matches the metadata criteria; and storing, by the data security system, the data record with the second label in the database.
8 . The method of claim 7 , further comprising:
receiving, by the data security system and via the user interface or the second user interface associated with the client account, a second rule associated with label generation, wherein the rule indicates a second metadata criteria and a third label, wherein the second metadata criteria overlaps at least in part with the metadata criteria, wherein the second rule has a lower priority than the rule; and identifying, by the data security system and based on the scan, that the metadata or the second metadata of the data record matches the metadata criteria; refraining from adding the third label to the data record based on adding the second label to the data record and based on the second rule having a lower priority than the rule.
9 . The method of claim 8 , further comprising:
identifying, by the data security system and based on the scan, a second data record of the plurality of data records that includes second metadata that matches the second metadata criteria; identifying, by the data security system and based on the scan, that the second metadata does not match the metadata criteria; adding, by the data security system, the third label to the second data record based on identifying that the second metadata of the data record matches the second metadata criteria and that the second metadata does not match the metadata criteria; and storing, by the data security system, the second data record with the third label in the database.
10 . The method of claim 7 , further comprising:
receiving, by the data security system and via the user interface, the second user interface, or a third user interface associated with the client account, a query that indicates the second label; retrieving, from the database and based on the query, a set of data records that include the second label, the set of data records including the data record; and causing, by the data security system, display of the set of data records at the user interface, the second user interface, or the third user interface.
11 . The method of claim 1 , further comprising:
receiving, by the data security system and via the user interface or a second user interface associated with the client account, a rule associated with label generation, wherein the rule indicates a metadata criteria and a second label; identifying, by the data security system and based on the scan, a second data record of the plurality of data records that includes second metadata that matches the metadata criteria; adding, by the data security system, the second label to the second data record based on identifying that the second metadata matches the metadata criteria; and storing, by the data security system, the second data record with the second label in the database.
12 . The method of claim 1 , wherein:
the transformation comprises a mathematical operation, and the type of metadata comprises a numeral and a unit.
13 . The method of claim 1 , wherein:
the transformation comprises a text transformation, and the type of metadata comprises a string type.
14 . The method of claim 1 , wherein:
the transformation comprises a list function, and the type of metadata comprises a list type.
15 . The method of claim 1 , wherein:
the transformation comprises a date operation, and the type of metadata comprises a date field.
16 . An apparatus, comprising:
one or more memories storing processor-executable code; and one or more processors coupled with the one or more memories and individually or collectively operable to execute the code to cause the apparatus to:
receive, by a data security system and via a user interface associated with a client account of the data security system, a function associated with label generation, wherein the function indicates a type of metadata and a transformation to apply to the type of metadata;
perform, by the data security system, a scan of a database that stores a plurality of data records associated with a respective plurality of computing assets associated with the client account, the plurality of data records comprising identifiers for the respective plurality of computing assets and metadata associated with the respective plurality of computing assets;
identify, by the data security system and based on the scan, a data record of the plurality of data records that includes metadata that matches the type of metadata;
generate, by the data security system, a label based on application of the transformation to the metadata in accordance with the function;
add, by the data security system, the label to the data record; and
store, by the data security system, the data record with the label in the database.
17 . The apparatus of claim 16 , wherein the one or more processors are individually or collectively further operable to execute the code to cause the apparatus to:
receive, by the data security system, a second data record associated with a second computing asset associated with the client account for addition to the database, the second data record comprising a second identifier and second metadata associated with the second computing asset; identify, by the data security system, that the second metadata matches the type of metadata; generate, by the data security system, a second label based on application of the transformation to the second metadata in accordance with the function; add, by the data security system, the second label to the second data record; and store, by the data security system, the second data record with the second label in the database.
18 . The apparatus of claim 16 , wherein the one or more processors are individually or collectively further operable to execute the code to cause the apparatus to:
identify, by the data security system and based on the scan, a second data record of the plurality of data records that includes second metadata that matches the type of metadata; generate, by the data security system, a second label based on application of the transformation to the second metadata in accordance with the function; add, by the data security system, the second label to the second data record; and store, by the data security system, the second data record with the label in the database.
19 . The apparatus of claim 16 , wherein the one or more processors are individually or collectively further operable to execute the code to cause the apparatus to:
receive, by the data security system and via the user interface or a second user interface associated with the client account, a second function associated with label generation, wherein the second function indicates a second type of metadata and a second transformation to apply to the second type of metadata; identify, by the data security system and based on the scan, that the data record includes second metadata that matches the second type of metadata; generate, by the data security system, a second label based on application of the second transformation to the second metadata in accordance with the function; add, by the data security system, the second label to the data record; and store, by the data security system, the data record with the second label in the database.
20 . A non-transitory computer-readable medium storing code, the code comprising instructions executable by one or more processors to:
receive, by a data security system and via a user interface associated with a client account of the data security system, a function associated with label generation, wherein the function indicates a type of metadata and a transformation to apply to the type of metadata; perform, by the data security system, a scan of a database that stores a plurality of data records associated with a respective plurality of computing assets associated with the client account, the plurality of data records comprising identifiers for the respective plurality of computing assets and metadata associated with the respective plurality of computing assets; identify, by the data security system and based on the scan, a data record of the plurality of data records that includes metadata that matches the type of metadata; generate, by the data security system, a label based on application of the transformation to the metadata in accordance with the function; add, by the data security system, the label to the data record; and store, by the data security system, the data record with the label in the database.Join the waitlist — get patent alerts
Track US2026080082A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.